PT-2017-2028 · Citrix · Citrix Netscaler Gateway

Published

2017-04-13

·

Updated

2017-07-11

·

CVE-2017-7219

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Citrix NetScaler Gateway versions 10.1 through 10.1 before 135.8/135.12 Citrix NetScaler Gateway versions 10.5 through 10.5 before 65.11 Citrix NetScaler Gateway versions 11.0 through 11.0 before 70.12 Citrix NetScaler Gateway versions 11.1 through 11.1 before 52.13
Description A heap overflow issue allows a remote authenticated attacker to execute arbitrary commands via unspecified vectors. The vulnerability is caused by a buffer overflow in the system's software, potentially enabling a remote attacker to exploit it.
Recommendations For versions 10.1 before 135.8/135.12, update to version 135.8/135.12 or later. For versions 10.5 before 65.11, update to version 65.11 or later. For versions 11.0 before 70.12, update to version 70.12 or later. For versions 11.1 before 52.13, update to version 52.13 or later.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01195
CVE-2017-7219

Affected Products

Citrix Netscaler Gateway